# Understanding the holehe `--no-password-recovery` Flag: Service Exclusions and Current Implementation

> Discover how the `--no-password-recovery` flag in holehe functions. Learn why no services are excluded and understand the current implementation status.

- Repository: [Palenath/holehe](https://github.com/megadose/holehe)
- Tags: deep-dive
- Published: 2026-08-29

---

**The `--no-password-recovery` flag in holehe does not exclude any services because the codebase currently lacks password-recovery implementations for all supported platforms.**

The `holehe` tool by megadose is an OSINT framework designed to check if an email address is registered across various online services. When investigating CLI options for security audits, users often question whether the `--no-password-recovery` (or `-NP`) flag filters out specific service modules. This article examines the actual implementation in the source code to clarify exactly which services are affected when this flag is activated.

## What Does the `--no-password-recovery` Flag Do?

The `--no-password-recovery` flag is defined in **[`holehe/core.py`](https://github.com/megadose/holehe/blob/main/holehe/core.py)** as a simple Boolean switch that instructs the CLI not to attempt password-recovery routines [(source)](https://github.com/megadose/holehe/blob/master/holehe/core.py#L190). 

Despite being available as a command-line option, the flag currently controls a capability that does not exist in the implementation. When parsed by the argument parser, it sets an internal state that would theoretically skip password-recovery attempts, but since no service modules contain this logic, the flag produces no functional filtering effect.

## Why No Services Are Currently Excluded

The Holehe codebase does **not** implement password-recovery logic for any of its service modules. Consequently, toggling this flag does not exclude any specific services from the email enumeration process.

All services continue to operate normally when the flag is present, executing only their standard email-existence checks. The tool queries each platform for account registration status regardless of whether `-NP` is specified, because none of the current modules attempt password-reset flows that would need suppression.

## Code Examples and CLI Usage

In practice, running holehe with or without the `--no-password-recovery` flag produces identical behavior in the current version:

```bash

# Standard execution - checks all services for email existence

holehe -e example@example.com

# Execution with password-recovery disabled - behavior is identical

# because no service implements password-recovery logic

holehe -e example@example.com --no-password-recovery

```

Both commands will iterate through the same service list and perform equivalent HTTP requests to verify if the target email is registered. The flag acceptance does not trigger service exclusion logic because the underlying recovery modules are absent from the codebase.

## Future Implications of the Flag

If future versions of holehe add password-recovery support for particular services, the `--no-password-recovery` flag will automatically suppress those attempts for **all** services that include such logic. 

At that point, the Boolean switch defined in [`core.py`](https://github.com/megadose/holehe/blob/main/core.py) would function as a master kill-switch, preventing any configured password-recovery routines from executing while still allowing standard account-existence enumeration to proceed. Until such features are implemented, the flag remains a placeholder for forward compatibility.

## Summary

- The `--no-password-recovery` flag is defined in [`holehe/core.py`](https://github.com/megadose/holehe/blob/main/holehe/core.py) as a Boolean CLI option but currently has no services to suppress.
- Zero service modules are excluded when using `-NP` because no password-recovery implementations exist in the current codebase.
- All standard email existence checks continue to run regardless of flag state.
- Future implementations of password-recovery features would respect this flag globally across all affected modules.

## Frequently Asked Questions

### Does `--no-password-recovery` skip specific service modules?

No. The flag does not filter or skip any service modules in the current implementation. According to the source code analysis, no modules contain password-recovery logic, so there are no services to exclude. The flag is parsed but does not alter the service execution list.

### Where is the flag defined in the holehe source code?

The flag is defined in **[`holehe/core.py`](https://github.com/megadose/holehe/blob/main/holehe/core.py)** around line 190 as a command-line argument. It accepts both the long form `--no-password-recovery` and the short form `-NP`, storing the value as a Boolean that controls whether password-recovery attempts should be permitted (though currently no such attempts are implemented).

### Will using `-NP` speed up holehe scans?

No. Since the flag does not currently disable any actual functionality, scan speed remains identical whether you include `--no-password-recovery` or omit it. The tool performs the same HTTP requests and processing steps in both scenarios because no password-recovery routines are being bypassed.

### Can I use `--no-password-recovery` with other flags?

Yes. The flag can be combined with other holehe CLI options such as `--only-used` or specific rate-limiting parameters. Being a simple Boolean toggle, it does not conflict with other arguments and will simply remain dormant until future versions implement the features it is designed to suppress.